Skip to content

Your Workforce and Their Families: Make Cybersecurity Awareness Month Relevant for Your Employees

Your Workforce and Their Families: Make Cybersecurity Awareness Month Relevant for Your Employees 


Most organizations now recognize human behavior is the most common way attackers get in.

Employees click links, trust urgent messages, reuse passwords, and make skewed judgment calls under pressure. Increasingly, those judgment calls are being manipulated by deepfakes and AI‑powered scams that target not just workers, but their families. 

If you’re serious about Human Risk Management (HRM) (and you should be!), Cybersecurity Awareness Month can be an excellent kickoff point for your workforce. To garner real engagement, make things personal, not just professional. When your campaign emphasizes that “human risk” lives at home, on personal devices, and in family group chats, you’ll see greater buy in to the behavior changes you’re hoping to see. 

Here's how to use Cybersecurity Awareness Month as a deliberate starting point for a broader HRM program. 

Why Human Risk Management must include families 

Traditional security awareness often draws a hard line between “work” and “home.” You teach people about phishing in their corporate inbox, password managers for business accounts, and MFA on enterprise tools. Meanwhile, their personal accounts, home Wi‑Fi, and family communication patterns get much less attention. 

But human beings don’t compartmentalize risk that neatly. If an employee learns strong security habits at work, they’re likely to bring some of those home. Conversely, if they are regularly manipulated or compromised in their personal life, those experiences shape how they respond to attacks against the organization. 

A mature HRM program recognizes this and asks: 

 

  • How can we support employees as whole people, not just as “users” of corporate systems? 

  • How can we help them recognize manipulation and deception wherever they encounter it—email, social media, voice calls, messaging apps? 

  • How can we equip them to protect their families, so they aren’t carrying constant anxiety and vulnerability into their workday? 

 

Answering those questions requires content and experiences that deliberately bridge work and home security. (That’s where October in a Box is intentionally different: it’s built to address both domains and to tee up a longer‑term HRM motion.) 

 

The rise of deepfakes and synthetic media at home 

A few years ago, deepfakes felt like a niche, almost novelty topic. Today, realistic fake audio and video are showing up in fraud, social engineering, and harassment cases. Attackers can synthesize a loved one’s voice, spin up convincing emergency stories, and use AI to make messages more believable and personalized. 

The impact is deeply personal: 

  • A parent gets a call that sounds exactly like their child, begging for urgent financial help. 

  • A spouse receives a video or voice note that appears to show a family member in distress, demanding immediate action. 

  • A relative is pressured into sharing sensitive information or credentials to “help” someone they care about. 

 

When families are targeted, employees bring emotional stress, distraction, and sometimes compromised accounts or devices into work. The household attack surface becomes part of the corporate attack surface. 

For HRM leaders, this matters because human risk isn’t just about employees as professionals—it’s about employees as people, embedded in networks of trust that extend well beyond their work identities. 

 

October in a Box: a starting point for whole person security 

 

At first glance, October in a Box looks like a comprehensive Cybersecurity Awareness Month package: four weeks of themed content, infographics, short messages for internal channels, an educational deepfake video, and supporting graphics. A strong “done‑for‑you” campaign. 

The even deeper value for HRM comes from how the program is designed: 

  • Each week’s content focuses on human‑error‑driven behaviors that matter at work and at home and emphasizes that employees don’t need intricate security knowledge to pause and verify. 

  • The deepfake awareness video shows how available tools are, and through a playful family example, demonstrates how face-swapping technology can be used to target and trick people. This makes the risk feel real in personal terms. 

  • The Family Cyber Incident Response Plan template is explicitly built for employees to use with their loved ones, translating organizational security principles into household action steps. 

By combining these elements, October in a Box frames Cybersecurity Awareness Month as a moment where the organization says: “We care about your safety and your family’s safety, not just our systems.” That’s a powerful trust‑building signal, and trust is the foundation of all great HRM programs. 

When employees feel that security is on their side—helping, not just enforcing—they are more likely to: 

  • Report suspicious activity promptly 

  • Engage with training and comms 

  • Ask questions when something feels off 

  • Share feedback on what’s working and what isn’t

 

In other words, Cybersecurity Awareness Month can be the opening chapter of a longer HRM story, not a one‑and‑done awareness check. 

 

Using October in a Box to launch an HRM program

 

If you want October in a Box to function as your HRM kickoff, you can treat the month as Phase 1 of a broader program rather than an isolated campaign. 

Here’s one way to do that: 

Frame October as “Phase 1: Awareness + Trust‑Building” 

In your initial communication, explain that this year’s Cybersecurity Awareness Month is the start of a sustained focus on human risk. Make it clear that the goal is not to scare people, but to empower them at work and at home. 

Highlight the family component early and often 
  • When you introduce the deepfake video and the Family Cyber Incident Response Plan, emphasize that these are resources for employees and their households. Invite them to share the plan, discuss scenarios, and adapt it to their reality. This sets the tone: HRM is about caring for people, not just protecting assets. 

Use weekly themes to gather insight 

  • As each week’s content goes out, pay attention to engagement and feedback. Which topics spark questions? Where do employees seem confused or worried? Collect this data as input for future HRM initiatives. 

Engage managers and people leaders as amplifiers 

  • Give managers talking points or quick discussion prompts tied to each week. When managers reinforce messages in team meetings, it signals that security isn’t just a siloed function; it’s part of how the organization operates. 

Close October with a roadmap, not a summary 

Instead of ending the month with “Thanks for participating,” close with a short roadmap: 

  • What you learned from responses and questions 

  • The behaviors you’ll keep focusing on 

  • The next HRM steps (ongoing nudges, event plans, and changes employees can expect) 

This makes it clear that October was the kickoff, not the whole program. 

Leverage the consultation hours to design Phase 2 

  • Use the expert time included with October in a Box to translate the month’s insights into a simple HRM roadmap. 

By the end of this process, you’ve done more than “run an awareness month.” You’ve created: 

  • A baseline of shared language about human risk 

  • Initial trust and goodwill by supporting employees and their families 

  • Concrete data on what resonates and where support is needed 

  • A visible commitment to keep working on behavior change over time 

That’s what an HRM program needs to grow. 

 

From campaign to culture: sustaining the momentum 

The real risk with any awareness initiative is that it fades as soon as the campaign ends. To avoid that, think of October in a Box as your cultural onramp. 

Once the month wraps, you can: 

  • Turn the Family Cyber Incident Response Plan into an annual or semi‑annual “check‑in” event, encouraging employees to update and revisit it with loved ones. 

  • Build simple, ongoing nudges around the behaviors that got the most traction, using the same tone and narrative you established in October. 

  • Gradually introduce more targeted HRM initiatives, like role‑based training, simulations, or design changes to controls, that align with the habits you’ve been promoting. 

  • From employees’ perspective, this looks like a consistent, human centered security presence in their work lives, not a once a year blast. From your perspective, it’s a manageable way to grow HRM capabilities without needing a huge program on day one. 

October in a Box gives you the structure, the content, and the initial credibility to start that journey.

 

What you build afterward is up to you; and if you want to make an impact, we’d love to help.  

About the author
Reveal Risk